Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: James Gough, Daniel Bryant, Matthew Auburn

Rating No ratings yet

Most organizations with a web presence build and operate APIs; the doorway for customers to interact with the company's services. Designing, building, and managing these critical programs affect everyone in the organization, from engineers and product owners to C-suite executives. But the real challenge for developers and solution architects is creating an API platform from the ground up. With this practical book, you'll learn strategies for building and testing REST APIs that use API gateways to combine offerings at the microservice level. Authors James Gough, Daniel Bryant, and Matthew Auburn demonstrate how simple additions to this infrastructure can help engineers and organizations migrate to the cloud; and open the opportunity to connect internal services using technologies like a service mesh. • Learn API fundamentals and architectural patterns for building an API platform • Use practical examples to understand how to design, build, and test API-based systems • Deploy, operate, and configure key components of an API platform • Use API gateways and service meshes appropriately, based on case studies • Understand core security and common vulnerabilities in API architecture • Secure data and APIs using threat modeling and technologies like OAuth2 and TLS • Learn how to evolve existing systems toward API- and cloud-based architectures

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, case-study-driven guide to designing, running, and evolving API platforms—from REST fundamentals and testing through gateways, service meshes, and security. Best for developers, solution architects, and technical leads who must make hard-to-reverse platform decisions. 【Book Arc】 - **Opening (~0%–10%)**: Frames APIs as the doorway to a company's services and introduces the running conference-system case study, C4 diagrams, and Architecture Decision Records (ADRs) as the book's decision-making backbone. - **Early (~10%–30%)**: Establishes API fundamentals—REST vs. RPC vs. GraphQL trade-offs, north–south vs. east–west traffic, and how to specify APIs with OpenAPI and version them safely. - **Middle (~30%–55%)**: Moves into testing and quality: the test quadrant and test pyramid, contract testing (consumer-driven vs. producer contracts), and tooling that catches breaking changes before consumers do. - **Late (~55%–80%)**: Covers operating the platform—API gateways, service meshes, deployment and release strategies, and operational concerns like SLAs, autoscaling, and security enforcement. - **Ending (~80%–100%)**: Deepens security with threat modeling (STRIDE, OWASP), authentication and authorization (OAuth2, JWT, TLS), and closes the loop on evolving legacy systems toward cloud-based API architectures. 【Key Takeaways】 - **Architecture is a journey, not a destination** (Early): The book's central stance is that you cannot predict technological change, so you evolve piece by piece rather than rewriting everything at once. - **ADRs turn "it depends" into documented decisions** (Early): Architecture Decision Records capture context, decision, and consequences; rejected ADRs are valuable and records are best kept immutable. - **Choose your API style by exchange type** (Early): REST suits stateless resource models, RPC favors performance in east–west service calls, and GraphQL addresses client-side query composition—each with different coupling trade-offs. - **OpenAPI plus diff tooling prevents breaking changes** (Middle): Specs are JSON/YAML descriptions of structure, domain objects, and security; running compatibility diffs in the pipeline catches renamed fields before consumers break. - **Testing strategy should be deliberate, not default** (Middle): The test quadrant and pyramid guide where to invest—unit tests at the base, service tests in the middle, UI tests at the peak—based on what matters for your system. - **Contract testing is worth the learning curve** (Middle): Defined, tested interactions save integration time; producer contracts matter most when exposing APIs to a large external audience. - **Gateways and service meshes are hard-to-undo decisions** (Late): The book gives opinionated guidance where warranted and a decision framework where options are less clear-cut. - **Security starts with threat modeling** (Ending): Think like an attacker, decompose the system, apply STRIDE, and secure data and APIs with OAuth2, JWT, and TLS. 【Reading Tips】 - **Deep-read the case study thread**: The conference system evolves throughout the book; tracking its changes is the fastest way to see concepts applied end to end. - **Skim the ADR guidelines on first pass, return later**: They are reference material for real decisions—bookmark the ones matching your current dilemma. - **Treat testing and security chapters as hands-on**: The OpenAPI diff commands and threat-modeling steps are meant to be tried, not just read. - **Use the C4 diagrams as your map**: When a chapter feels abstract, return to the diagrams to re-anchor which component is being discussed. - **Take away the decision frameworks, not just the answers**: The book's value is in how to choose gateways, meshes, and API styles for your own context. 【Coverage Limits】 This guide is synthesized from stratified excerpts covering the introduction, early design and testing chapters, and table-of-contents-level views of later security and operations material; specific implementation details of gateway, mesh, and cloud-migration chapters are only partially represented.
Page 11
Guideline: Separating Release from Deployment with Traffic Management and Feature Flags 131 Release Strategies 131 Canary Releases 131 Traffic Mirroring 133...
View in text
Excerpt 2
without a destination, and you cannot predict how technol‐ ogies and architectural approaches will change. For example, you may not have been able to predict...
View in text
Excerpt 3
ere are a range of guidelines to choose from, including the Microsoft guidelines discussed in this section, and finding one that best matches the styles of A...
View in text
Excerpt 4
) headers { contentType('application/json') } body( value: [ id: 123456, givenName: 'James', familyName: 'Gough' id: 123457, givenName: 'Matthew', familyName...
View in text
Excerpt 5
that you write as part of your end-to-end testing should be focused on ensuring that you are still serving requests within your targeted SLOs. You want these...
View in text
Excerpt 6
ll have a large number of layers in your edge stack and are migrating to the cloud or a new platform, now is the time to potentially think about the trade-of...
View in text
Excerpt 7
erformance, security, and (cloud vendor) cost implications. Let’s now explore how a service mesh can help you meet your new requirements while avoiding this...
View in text
Excerpt 8
orm, be it a programming language or a runtime like the JVM. If you use platforms other than the one supported by the library, you will most likely need to p...
View in text
Tags
AI categories
API ArchitectureCloud NativeSoftware
ISBN: 1492090638
Publisher: O'Reilly Media
Publish Year: 2022
Language: English
Pages: 289
File Format: PDF
File Size: 9.3 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…